Phishing remains the cheapest attack and the most expensive mistake in 2026: one in three employees (33.2%) will engage with a malicious email before any training, and the average Australian small business loses $56,571 per cybercrime incident. The numbers below come from KnowBe4's 2026 benchmark of 14.5 million users, Verizon's 2025 Data Breach Investigations Report and the Australian Signals Directorate's 2024-25 Annual Cyber Threat Report.
TL;DR
- 33.2% of employees are likely to click a phishing email or comply with a fraudulent request before any training (KnowBe4, 2026).
- Twelve months of continuous training and simulation cuts that to 4.2% - an 87% reduction.
- Roughly 60% of breaches involve a human element (Verizon 2025 DBIR); the 2026 edition put it at 62%.
- Australian small business cybercrime cost averaged $56,571 per report in 2024-25, up 14% year on year (ASD).
- One cybercrime report reaches the Australian regulator every 6 minutes.
Phishing click rates before and after training
KnowBe4's 2026 Phishing by Industry Benchmarking Report analysed millions of simulated phishing tests across 19 industries and four organisation sizes. Its Phish-prone Percentage (PPP) - the share of staff likely to engage with a malicious email - moves like this:
| Programme stage | Click-prone share of staff |
|---|---|
| Before any training | 33.2% |
| After 90 days of training | 20.1% |
| After 12 months of training | 4.2% |
The first 90 days remove about 40% of the risk; a full year cuts it by 87%. The improvement comes only from continuous programmes - monthly training plus monthly phishing simulations.
Click rates by organisation size
| Organisation size | Baseline click-prone share |
|---|---|
| Under 250 staff | 24.7% |
| Over 10,000 staff | 39.5% |
Larger attack surfaces and more complex communication environments give attackers more to imitate - which is why enterprises carry the higher baseline, and why small businesses should not read their lower figure as safety.
The human element in breaches
Verizon's 2025 DBIR puts the human element - error, misuse, or social engineering - behind roughly 60% of breaches, a figure that has held steady for years. The 2026 edition measured it at 62%, even as exploit-driven intrusions grew: technical walls keep getting better at blocking mass campaigns, so attackers invest in the person instead.
What cybercrime costs Australian businesses
The Australian Signals Directorate's Annual Cyber Threat Report 2024-25 tracks the self-reported cost of cybercrime per report:
| Business size | 2024-25 average cost | Change |
|---|---|---|
| Small business | $56,571 | up 14% |
| Medium business | $97,166 | up 55% |
| Large business | $202,691 | up 219% |
Other 2024-25 figures worth knowing:
- 84,700 cybercrime reports were filed with ReportCyber - one every 6 minutes.
- Email compromise accounted for the largest share of business reports, including incidents where no money moved but data or credentials did.
- Ransomware featured in 11% of all incidents ASD responded to, and in 35% of those cases victim data was posted online.
Reporting: the counter-statistic nobody tracks
Click rate is only half the picture. The share of simulated phishing emails reported before anyone clicks is the reflex that stops real incidents - every reported email is an early warning that costs the attacker their head start. Track both alongside training completion in a monthly human risk reporting score; a rising report rate with a falling click rate is what a healthy programme looks like.
What the numbers mean for a small business
One in three staff clicking, an average incident cost above $56,000, and an 87% risk reduction available for a fraction of that spend - the arithmetic points one direction. Start with a baseline simulation, train monthly, and hold the programme to the benchmark trajectory: click-prone share near 20% by day 90 and near 4% by month twelve. The employee training guide walks through the full programme setup.
FAQ
What percentage of employees fall for phishing in 2026? Globally, 33.2% before any training (KnowBe4, 2026). Small organisations under 250 staff average 24.7%; enterprises over 10,000 staff average 39.5%.
How much does training reduce phishing clicks? By 87% at the twelve-month mark - from 33.2% to 4.2% click-prone share - when training and simulations run continuously.
What share of breaches involve human error or phishing? About 60% (Verizon 2025 DBIR); the 2026 edition measured 62%. It has been the single largest breach ingredient every year the report has run.
How much does a cyber incident cost a small Australian business? The 2024-25 average self-reported cost is $56,571 per incident, up 14% on the prior year (ASD).
How often are Australians reporting cybercrime? One report every 6 minutes - 84,700 reports to ReportCyber in 2024-25.